lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [month] [year] [list]
Date: Mon, 4 Dec 2006 17:28:05 +0100
From: ss_team <ssteam.pl@...il.com>
To: bugtraq@...urityfocus.com
Subject: Symantec LiveState Agent for Windows vulnerability - Local Privilege Escalation

hello,

we've found local privilege escalation in Symantec LiveState agent.

PoC:

1. kill shstart.exe process
2. from symantec livestate agent icon in systray choose "Web Self-Service"
3. New browser window will open, it is running with SYSTEM privileges.

tested on fully patched Win XP SP2, Symantec LiveState agent 7.1


Credits: marc & shb


-- 
http://ssteam.ath.cx

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux